CVE-2026-25681: Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Other sources
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.7.11-7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.5.1-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.14.0-15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.30.10-25 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.2.4-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.27.0-13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.62.0-17 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.7.0-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.14.1-14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.31.0-23 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.2-9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.4.0-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.8.1-4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.1-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.12.0-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.0.10-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.9.5-14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.12.15-8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.7.5-17 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.7-4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.32.0-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.62.0-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.2.4-4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25681?
The severity of CVE-2026-25681 is rated at 59, indicating a moderate risk level.
How do I fix CVE-2026-25681?
To fix CVE-2026-25681, update to the latest version of the go/golang.org/x/net/html package that addresses this vulnerability.
What applications are affected by CVE-2026-25681?
Applications using the go/golang.org/x/net/html package to parse and render HTML are vulnerable to CVE-2026-25681.
What type of attack can CVE-2026-25681 lead to?
CVE-2026-25681 can lead to Cross-Site Scripting (XSS) attacks due to incorrect handling of character references in DOCTYPE nodes.
When was CVE-2026-25681 published?
CVE-2026-25681 was published on May 22, 2026.